{"title":"Discovery inventory","version":"v1","summary":"Send an origin. We GET the catalog paths we already inventory on ourselves (menu.json, x402, OpenAPI, A2A, llms.txt, skill.md, and the well-known cousins), hash what answered, extract identity claims, and join them. Free, no account, unsigned. Facts and disagreements, never a score.","method":"POST","url":"https://scvd.store/api/discovery/v1","request":{"url":"REQUIRED. The https origin to inventory. Paths are ours — a caller does not choose what we fetch, only whose host."},"candidate_paths":["/menu.json","/llms.txt","/skill.md","/openapi.json","/.well-known/x402.json","/.well-known/x402","/.well-known/a2a.json","/.well-known/mcp","/agents.md"],"rate_limit":"Two ceilings, both ours: 8 inventories/minute per isolate and 20/minute globally. Past either you get a 429 that says the budget is our cost bound, not a fact about their catalogs. One call fetches every candidate path.","what_it_returns":["Each candidate path: status, sha256 when the body was read, extracted claim values.","Disagreements from the same join we run on ourselves — only_left / only_right, no score.","derived.verdict: agree | conflict | not_observed (not_observed when fewer than two surfaces produced claims).","compared_to: null on a first look; otherwise the surfaces and claims that moved since the last look we stored. Not a watch. Does not alert."],"what_it_cannot_check":["same_operator — refused (G2).","Whether the live buy door still behaves like these catalogs.","MCP cluster item ids — we do not call tools/list in your name.","This store's own hostname — the platform kills self-fetch; CI joins our catalogs."],"signed":false,"next_steps":{"self_row":"Our own catalogs are joined in CI. Probe this door from outside if you want a reading of us.","signed_report":"The signer is built. A report, once issued, is free to read at https://scvd.store/api/discovery/report/{id}. The SKU that issues one is not priced yet — this door does not sell a signature."}}